Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/17988 |
|
History
Fri, 10 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins. | |
| Title | Livestatus injection in monitoring quicksearch | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-140 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-04-10T08:30:20.089Z
Reserved: 2026-03-20T10:30:13.352Z
Link: CVE-2026-33455
No data.
Status : Received
Published: 2026-04-10T09:16:23.447
Modified: 2026-04-10T09:16:23.447
Link: CVE-2026-33455
No data.
OpenCVE Enrichment
No data.
Weaknesses